package com.project.controller;

import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpSession;

@RestController
public class UserController {

    @RequestMapping("login")
    public String login(String userName, String pwd, String code, HttpServletRequest req){
        //得到用户的session对象
        HttpSession session = req.getSession();
        //取出验证码共享数据
        String loginCode = session.getAttribute("loginCode").toString();
        if(code.equalsIgnoreCase(loginCode) == false){//判断验证码是否正确
            return "验证码错误";
        }

        if("java".equals(userName) && "123".equals(pwd)){
            return "ok";
        }
        return "no";
    }
}
